Auto-tuning permissions using a learning mode
Abstract
Methods, systems, and computer-readable media for auto-tuning permissions using a learning mode are disclosed. A plurality of access requests to a plurality of services and resources by an application are determined during execution of the application in a learning mode in a pre-production environment. The plurality of services and resources are hosted in a multi-tenant provider network. A subset of the services and resources that were used by the application during the learning mode are determined. An access control policy is generated that permits access to the subset of the services and resources used by the application during the learning mode. The access control policy is attached to a role associated with the application to permit access to the subset of the services and resources in a production environment.
Claims
exact text as granted — not AI-modified1 .- 20 . (canceled)
21 . A system, comprising:
one or more computing devices configured to implement an access control management system, configured to:
generate an effective access control policy for a principal in a computing environment, wherein the effective access control policy aggregates permissions specified in a set of access control policies associated with the principal;
monitor, during a learning mode, access requests of the principal to a plurality of services and resources in the computing environment under the effective access control policy;
determine, based at least in part on the access requests of the principal observed during the learning mode, that one or more permissions in the effective access control policy are associated with one or more unused service or resources; and
remove the one or more permissions from the effective access control policy in response to the determination that the one or more permissions are associated with one or more unused service or resources.
22 . The system as recited in claim 21 , wherein the set of access control policy includes two or more of a delegation policy, a resource policy, a user account policy, a user group policy, a role policy, and an organization policy.
23 . The system as recited in claim 21 , wherein effective access control policy automatically changes as the set of access control policies associated with the principal changes.
24 . The system as recited in claim 21 , wherein a particular policy in the set of access control policies is a temporarily policy that is temporarily associated with the principal.
25 . The system as recited in claim 21 , wherein the principal is associated with an application in the computing environment and the effective access control policy is associated with the application.
26 . The system as recited in claim 25 , wherein the learning mode is conducted during a pre-production phase of the application and the access requests are generated in response to historical or synthetic client traffic.
27 . The system as recited in claim 21 , wherein to generate the effective access control policy, the access control management system is configured to:
resolve a permission conflict between two or more access control policies in the set of access control policies; or remove a redundant permission between two or more access control policies in the set of access control policies.
28 . The system as recited in claim 21 , wherein to remove the one or more permissions from the effective access control policy, the access control management system is configured to:
perform one or more removal actions selected from a set of removal actions, the set of removal actions including two or more of:
(a) removing the principal from a group,
(b) releasing the principal from a role,
(c) modifying permissions of a group or a role,
(d) adding the principal to a new group with different permissions, and
(e) deprovisioning a service or resource.
29 . The system as recited in claim 21 , wherein to remove the one or more permissions from the effective access control policy, the access control management system is configured to:
split a group associated with the principal into two or more groups with different permissions; and assign the principal to one of the two or more groups.
30 . The system as recited in claim 21 , wherein the computing environment is provided by a multi-tenant resource provider network that provides virtualized compute and storage resource for a plurality of tenants.
31 . The system as recited in claim 21 , wherein the access control management system is configured to:
modify the effective access control policy based at least in part on whether a number of access requests observed for a particular service or resource during the learning mode exceeds a threshold.
32 . The system as recited in claim 21 , wherein the access control management system is configured to:
add a particular permission to the effective access control policy based at least in part on the access requests observed during the learning mode.
33 . A method, comprising:
performing, by an access control management system implemented by one or more computing devices:
generating an effective access control policy for a principal in a computing environment, wherein the effective access control policy aggregates permissions specified in a set of access control policies associated with the principal;
monitoring, during a learning mode, access requests of the principal to a plurality of services and resources in the computing environment under the effective access control policy;
determining, based at least in part on the access requests of the principal observed during the learning mode, that one or more permissions in the effective access control policy are associated with one or more unused service or resources; and
removing the one or more permissions from the effective access control policy in response to the determination that the one or more permissions are associated with one or more unused service or resources.
34 . The method as recited in claim 33 , wherein the set of access control policy includes two or more of a delegation policy, a resource policy, a user account policy, a user group policy, a role policy, and an organization policy.
35 . The method as recited in claim 33 , wherein effective access control policy automatically changes as the set of access control policies associated with the principal changes.
36 . The method as recited in claim 33 , wherein a particular policy in the set of access control policies is a temporarily policy that is temporarily associated with the principal.
37 . The method as recited in claim 33 , wherein generating the effective access control policy comprises:
resolving a permission conflict between two or more access control policies in the set of access control policies; or removing a redundant permission between two or more access control policies in the set of access control policies.
38 . The method as recited in claim 33 , wherein removing the one or more permissions from the effective access control policy comprises:
performing one or more removal actions selected from a set of removal actions, the set of removal actions including two or more of:
(a) removing the principal from a group,
(b) releasing the principal from a role,
(c) modifying permissions of a group or a role,
(d) adding the principal to a new group with different permissions, and
(e) deprovisioning a service or resource.
39 . The method as recited in claim 33 , wherein removing the one or more permissions from the effective access control policy comprises:
splitting a group associated with the principal into two or more groups with different permissions; and assigning the principal to one of the two or more groups.
40 . The method as recited in claim 33 , further comprising the access control management system:
generating a recommendation to remove the one or more permissions from the effective access control policy, wherein the removing of the one or more permissions is performed in response a user approval of the recommendation.Join the waitlist — get patent alerts
Track US2024223618A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.